US11734196B1ActiveUtility

Decrypting secure packages in a storage network

Assignee: PURE STORAGE INCPriority: Nov 28, 2011Filed: Mar 10, 2021Granted: Aug 22, 2023
Est. expiryNov 28, 2031(~5.4 yrs left)· nominal 20-yr term from priority
G06F 12/1408G06F 11/1004G06F 11/1076H04L 9/085H04L 9/0894H04L 9/14H04L 9/3239H04L 9/3263H04L 63/061H04L 67/06H04L 67/1097H04L 67/306G06F 2212/1052H04L 1/0041H04L 1/0045H04L 63/0428
69
PatentIndex Score
0
Cited by
106
References
20
Claims

Abstract

A method for execution by a computing device of a storage network includes dispersed storage error decoding a plurality of sets of encoded data slices to recover a plurality of secure packages, where the plurality of secure packages include a plurality of encrypted data segments and a plurality of sets of encoded key slices, and where encoded key slices are appended to the encrypted data segments in accordance with an appending approach. The method includes splitting the plurality of secure packages into the plurality of encrypted data segments and the plurality of sets of encoded key slices. The method includes decoding the at least the decode threshold number of each set of the plurality of sets of encoded key slices to recover a plurality of encryption keys. The method includes decrypting the plurality of encrypted data segments using the plurality of encryption keys to recover the data segments.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A method for execution by a computing device of a storage network comprises:
 dispersed storage error decoding, by the computing device, a plurality of sets of encoded data slices to recover a plurality of secure packages, wherein the plurality of secure packages include a plurality of encrypted data segments and a plurality of sets of encoded key slices, wherein at least a decode threshold number of encoded key slices of a set of encoded key slices of the plurality of sets of encoded key slices are appended to at least some of the encrypted data segments in accordance with an appending approach to produce a secure package of the plurality of secure packages, and wherein the encrypted data segments were not dispersed storage error encoded prior to the appending the at least a decode threshold number of encoded key slices to the at least some of the encrypted data segments; 
 splitting, by the computing device, the plurality of secure packages into the plurality of encrypted data segments and the plurality of sets of encoded key slices; 
 dispersed storage error decoding, by the computing device, the plurality of sets of encoded key slices to recover a plurality of encryption keys; and 
 decrypting, by the computing device, the plurality of encrypted data segments using the plurality of encryption keys to recover data segments. 
 
     
     
       2. The method of  claim 1  further comprises:
 de-segmenting, by the computing device, at least some of the data segments to recover a data object. 
 
     
     
       3. The method of  claim 1  further comprises:
 obtaining the plurality of sets of encoded data slices from storage units of the storage network. 
 
     
     
       4. The method of  claim 1 , wherein the appending approach includes:
 appending, by the computing device, an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices. 
 
     
     
       5. The method of  claim 1 , wherein the appending approach includes:
 appending, by the computing device, an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a pseudo random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices. 
 
     
     
       6. The method of  claim 1 , wherein the appending approach includes:
 appending, by the computing device, an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments according to a function, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices. 
 
     
     
       7. The method of  claim 1  wherein the plurality of encryption keys were dispersed storage error encoded into the plurality of sets of encoded key slices using a key dispersed storage error encoding function. 
     
     
       8. The method of  claim 7 , wherein the secure packages were dispersed storage error encoded into the plurality of sets of encoded data slices using a dispersed storage error encoding function. 
     
     
       9. The method of  claim 8 , wherein the key dispersed storage error encoding function has a first pillar width, a first decode threshold, and a first error encoding function, and the dispersed storage error encoding function has a second pillar width, a second decode threshold, and a second error encoding function. 
     
     
       10. The method of  claim 1 , wherein a data segment of the data segments was encrypted using an encryption key of the plurality of encryption keys to produce an encrypted data segment of the encrypted data segments. 
     
     
       11. A computing device of a storage network, the computing device comprises:
 an interface; 
 memory; and 
 a processing module operably coupled to the memory and the interface, wherein the processing module is operable to: 
 dispersed storage error decode a plurality of sets of encoded data slices to recover a plurality of secure packages, wherein the plurality of secure packages include a plurality of encrypted data segments and a plurality of sets of encoded key slices, wherein at least a decode threshold number of encoded key slices of a set of encoded key slices of the plurality of sets of encoded key slices are appended to at least some of the encrypted data segments in accordance with an appending approach to produce a secure package of the plurality of secure packages, and wherein the encrypted data segments were not dispersed storage error encoded prior to the appending the at least a decode threshold number of encoded key slices to the at least some of the encrypted data segments; 
 split the plurality of secure packages into the plurality of encrypted data segments and the plurality of sets of encoded key slices; 
 dispersed storage error decode the at least the decode threshold number of each set of the plurality of sets of encoded key slices to recover a plurality of encryption keys; and 
 decrypt the plurality of encrypted data segments using the plurality of encryption keys to recover data segments. 
 
     
     
       12. The computing device of  claim 11 , wherein the processing module is further operable to:
 de-segment at least some of the data segments to recover a data object. 
 
     
     
       13. The computing device of  claim 11 , wherein the processing module is further operable to:
 receive, via the interface, the plurality of sets of encoded data slices from storage units of the storage network. 
 
     
     
       14. The computing device of  claim 11 , wherein the processing module is further operable to perform the appending approach by:
 appending an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices. 
 
     
     
       15. The computing device of  claim 11 , wherein the processing module is further operable to perform the appending approach by:
 appending an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a pseudo random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices. 
 
     
     
       16. The computing device of  claim 11 , wherein the processing module is further operable to perform the appending approach by:
 appending an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments according to a function, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices. 
 
     
     
       17. The computing device of  claim 11 , wherein the plurality of encryption keys were dispersed storage error encoded into the plurality of sets of encoded key slices using a key dispersed storage error encoding function. 
     
     
       18. The computing device of  claim 17 , wherein the secure packages were dispersed storage error encoded into the plurality of sets of encoded data slices using a dispersed storage error encoding function. 
     
     
       19. The computing device of  claim 18 , wherein the key dispersed storage error encoding function has a first pillar width, a first decode threshold, and a first error encoding function, and the dispersed storage error encoding function has a second pillar width, a second decode threshold, and a second error encoding function. 
     
     
       20. The computing device of  claim 11 , wherein the processing module is further operable to encrypt a data segment of the data segments using an encryption key of the plurality of encryption keys to produce an encrypted data segment of the encrypted data segments.

Join the waitlist — get patent alerts

Track US11734196B1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.